Google Fined €403m by Irish Data Watchdog for GDPR Breaches Over Location Data Tracking
Ireland's Data Protection Commission has imposed a €403 million fine on Google following a six-year inquiry into the company's processing of users' location data, finding that the technology giant breached GDPR requirements on lawfulness, fairness, transparency, and data retention across three of its most widely used features.
Background
The Data Protection Commission launched its own-volition inquiry into Google's location data practices in February 2020, following complaints from a coalition of European consumer rights organisations including the European Consumer Organisation and the Norwegian Consumer Council. The inquiry focused on the period between May 2018 — when the GDPR came into force — and February 2020, examining how Google processed location data through three specific features: Web and App Activity, Location History, and Location Accuracy.
The DPC, which serves as the lead supervisory authority for Google in the European Union by virtue of the company's European headquarters being located in Dublin, has become one of the most active data protection regulators in the world since the GDPR's introduction. The commission has previously imposed significant fines on Meta and TikTok, and the Google decision is the fourth-largest penalty it has issued to date. The DPC is led by Commissioners Dr. Des Hogan, Dale Sunderland, and Niamh Sweeney.
Location data is classified as particularly sensitive under the GDPR because of its capacity to reveal intimate details about individuals' lives — their religious practices, political affiliations, health conditions, and personal relationships — through the pattern of their movements. The commission's inquiry examined whether Google had been sufficiently transparent with users about how their location data was being collected, retained, and used to target them with advertising.
Key Developments
The DPC's decision, published on Monday, September 21, found that Google had infringed GDPR requirements on the lawfulness and fairness of processing in relation to its Web and App Activity and Location History features. The commission also found that Google had failed to meet its transparency obligations across all three features, and that the company had retained users' location data for longer than was necessary — a finding the DPC noted aggravated the loss of user control over personal information.
The Location Accuracy feature, which operates on Android devices regardless of whether a user is signed into a Google account, was found to have failed to demonstrate compliance with GDPR requirements on lawfulness, fairness, and transparency. The commission found that users were potentially unaware that their movements were being tracked to influence them with targeted advertisements or to infer their personal interests.
Google has been ordered to bring its processing activities into full compliance with the GDPR within six months. The company stated that the ruling concerns historical policies that have since been updated, noting that it has evolved its practices since 2019 to include tools for automatic data deletion and improved advertising management. Google indicated it may appeal aspects of the ruling that require further legal clarification.
Why It Matters
The €403 million fine is significant not merely for its size but for what it signals about the DPC's willingness to take on the largest technology companies in the world on behalf of European users. The commission has faced criticism in the past — including from the European Data Protection Board — for being too slow and too lenient in its enforcement actions against the major US technology platforms headquartered in Ireland. This decision, coming after a six-year inquiry, demonstrates that the DPC is capable of reaching substantial conclusions, even if the timeline remains a concern for privacy advocates.
For Irish users of Google's services — and that means virtually every smartphone user in the country — the decision is a reminder that the data generated by their daily movements has commercial value that they may not fully appreciate. The GDPR was designed to give individuals meaningful control over their personal data, but that control is only meaningful if it is enforced. The DPC's decision sends a clear message that the passive collection of location data without adequate transparency will not be tolerated under European law.
Local Impact
Google's European headquarters is located in Dublin's Silicon Docks, and the company is one of Ireland's largest private sector employers, with thousands of staff based in the capital. The fine will not affect Google's operations in Ireland in any material way — €403 million represents a fraction of the company's annual revenue — but it reinforces Dublin's position as the de facto regulatory capital of the European technology sector. The DPC's decision will be scrutinised by data protection authorities across the EU, and its reasoning is likely to inform future enforcement actions against other technology companies. Irish privacy advocates have welcomed the decision while noting that the six-year timeline for the inquiry is far too long for effective enforcement.
What's Next
Google has six months to bring its location data processing practices into full compliance with the GDPR. The company is expected to file an appeal against aspects of the decision in the Irish courts, a process that could take several years to resolve. The DPC has indicated it will monitor Google's compliance closely and will take further action if the company fails to meet the six-month deadline. The European Data Protection Board, which coordinates enforcement across EU member states, has been notified of the decision and may issue guidance on its implications for other data controllers processing location data.




